What personal data is collected, why it is held, who it is shared with, and how long it is kept.
Last updated 12 August 2026 · Applies to dwipanjithandique.in and the client dashboard
This policy explains how Dwipanjit Handique, a Research Analyst registered with the Securities and Exchange Board of India under registration number INH000028936 ("I", "me"), handles personal data. It covers this website, the client dashboard, and the onboarding process used to take on a research client.
The short version. I collect the information needed to verify who you are, to enter into a research agreement with you, to take payment, and to deliver research. I do not sell personal data, I do not share it for advertising, and I do not use it to profile you for anything other than the service you asked for. Some of it I am legally required to keep for at least five years even after you leave.
Dwipanjit Handique, SEBI Registered Research Analyst, registration number INH000028936, is the data fiduciary for the personal data described here. Contact details are at the end of this page. There is no separate company: this is an individual registration, and I am personally accountable for the data.
| Data | Why it is collected | Where it comes from |
|---|---|---|
| Name, email address, mobile number | To identify you, to contact you about your subscription, and to send the agreement and receipts | You, or your Google account if you sign in with Google |
| PAN and date of birth | Mandatory for KYC. SEBI requires a Research Analyst to verify a client's identity through a KYC Registration Agency before taking them on | You |
| KYC record: address, identity and address proof references, and related fields held by the KRA | To confirm your KYC is valid and to keep the client record SEBI requires | Retrieved from the KRA, not typed in by me |
| Risk profile and suitability answers | To assess whether a research service is suitable for you, as SEBI requires before recommending it | You |
| Signed agreement and Most Important Terms and Conditions, with the eSign audit trail | Evidence that a valid agreement exists, which SEBI requires me to hold | You, through the eSign provider |
| Payment records: amount, date, reference, method, and the last four digits of a card where the gateway returns them | To confirm payment, issue receipts, calculate refunds, and meet accounting and audit obligations | The payment gateway |
| Telegram username or user id, where you take delivery through Telegram | To add you to the research channel for the plan you paid for, and to remove you when it ends | You, through Telegram |
| Service records: which plan, when it started and ended, complaints, and correspondence | To run the service and to maintain the registers SEBI requires a Research Analyst to keep | Generated by the service |
| Technical logs: IP address, browser type, timestamps of sign-in and key actions | Security, fraud prevention, and the audit trail that shows who did what and when | Automatically, when you use the site |
What is never collected here. I do not ask for and do not store your Aadhaar number, your bank account number, your card number, your card expiry, your CVV, your UPI PIN, or any password to another service. Card and UPI details are entered on the payment gateway's own screen and never reach my server. Where Aadhaar is used at all, it is used inside the KRA's own verified process, and only a masked reference comes back.
These are the only categories of recipient, and each receives only what it needs to do its job.
| Recipient | What they receive | Why |
|---|---|---|
| KFIN Technologies (KFIN KRA), a SEBI-registered KYC Registration Agency | PAN, date of birth, name, mobile, email, and the KYC record | To check and record your KYC, which SEBI requires before a client is taken on |
| The eSign provider (Leegality, and the licensed eSign service behind it) | Name, email, mobile, and the agreement document | To have the agreement signed electronically with a legally valid signature |
| The payment gateway (Razorpay) | Name, email, mobile, amount, and the order reference | To take payment and to process refunds. Your card, netbanking or UPI credentials are handled entirely by them and are never seen by me |
| Telegram, where you choose delivery through Telegram | Your Telegram username or user id only | To give and withdraw access to the research channel for your plan |
| Email delivery provider | Your email address and the message being sent | To deliver agreements, receipts and service email |
| SEBI, BSE, a designated Research Analyst Administration and Supervisory Body, an auditor, or a court or law-enforcement authority | Whatever the applicable regulation, inspection, audit or lawful order requires | Legal and regulatory obligation. I cannot refuse a lawful request, and I do not treat this as optional |
I do not sell personal data. I do not share it with advertisers or data brokers. I do not use it to train any machine-learning model, mine or anyone else's.
Data is stored on servers located in India, and the vendors named above operate in India under Indian regulation. Where a technical service processes data outside India, it is limited to what that service needs and to countries not restricted by the Government of India for such transfers.
This is why a request to delete everything cannot always be granted in full while the retention period runs. I will say so plainly and delete what is not caught by it, rather than quietly ignoring the request.
You may ask me to:
Write to dwipanjit.researchanalyst@gmail.com. I acknowledge within 3 working days and respond within 7 business working days, which is the same timetable SEBI sets for resolving a grievance. There is no charge.
The site uses cookies that are necessary for it to work: keeping you signed in, and protecting forms against cross-site request forgery. These cannot be switched off without breaking sign-in. If analytics or any non-essential cookie is introduced later, this section will say so and consent will be asked for before it is set, not after.
The visit count shown in the footer. This page counts visits so a figure can be published, and it is built to hold nothing about you. No cookie is set for it. Your browser keeps a single flag in sessionStorage so that one visit is counted once rather than once per page you open; that flag is erased when you close the tab and is never sent anywhere. What reaches the server is a request carrying no identifier, and what the server keeps is one row per day holding a date and a number — no IP address, no hash of one, no device or browser details, nothing that could be traced to a person. There is therefore nothing in that record to ask consent for, to disclose to you on request, or to lose in a breach.
One qualification, stated because it is true rather than because it has to be: the request is rate-limited by IP address, as every public endpoint on this site is, so that the published figure cannot be inflated by repeatedly reloading the page. That address is held in memory for the length of the limit window and is not written to disk or to any record.
Because the count cannot tell a returning reader from a new one, the footer says visits. It is not a count of people, of investors, or of clients, and it is not presented as one.
The site is served over HTTPS. Vendor keys and other secrets are encrypted at rest and are never displayed back once saved, so they can be replaced but not read out. Access to the administration console is restricted and every action is written to an audit trail with who did it and when. Payment credentials never touch my server, because they are entered on the gateway's own screen.
No system is perfect. If a breach occurs that is likely to affect you, I will inform you and the Data Protection Board of India as the law requires, and tell you what happened rather than minimising it.
Research services are not offered to anyone under 18. If a minor's data reaches me, it is deleted once identified.
If this policy changes, the revised version is published here with a new date at the top. Where a change materially affects how your data is used, existing clients are told by email rather than left to notice it.
Dwipanjit Handique
SEBI Registered Research Analyst · Registration No. INH000028936
Email: dwipanjit.researchanalyst@gmail.com
Phone: +91 88220 68674
C/o House No. 5, 2nd Floor, Laxminath Bezbaruah Path, Hatigaon, Guwahati – 781038, Assam
If you are not satisfied with how a privacy matter has been handled, you may escalate to the Data Protection Board of India. For matters concerning research services, you may also use SEBI's SCORES portal or the SMART ODR platform. Details of the grievance process are on the home page.